Blackhat 2026

Before You Talk to an AI Security Vendor at Black Hat, Be Ready To Ask These 5 Questions.

Click below to get a two-page field guide to help you separate real AI security capabilities from existing web-security technology with AI features added.

Black Hat will have no shortage of AI security claims.

AI visibility. AI governance. DLP for AI. Shadow AI. Agent security. Zero Trust for AI.

The terminology is starting to sound remarkably similar.

The architectures behind those claims are not.

We created 5 Questions to Ask Every AI Security Vendor to help security and IT teams get past the standard pitch and understand what a product can actually see, control and protect.

No registration. Keep it on your phone and use it on the show floor.


The 5 questions

1. Can you stop sensitive data before it reaches the AI service?

Don’t just ask whether a vendor provides DLP for AI.

Ask where the inspection actually happens — and whether it can inspect prompts, clipboard content, file uploads and desktop AI activity before sensitive information leaves the endpoint.


2. How do you secure AI that never passes through your cloud?

Employees aren’t only using AI through browser tabs.

Ask what happens with desktop applications, local AI assistants, browser extensions, coding tools and autonomous agents — particularly when their traffic doesn’t traverse the vendor’s cloud service.


3. Can you show me every AI tool and agent in use?

“AI visibility” can mean very different things.

Ask the vendor to distinguish between browser-based AI, desktop clients, browser extensions, API calls and local agents.

Then ask what happens when the AI application isn’t already in their known application database.


4. How do you apply Zero Trust to AI agents accessing company data?

Finding AI is only part of the problem.

As autonomous agents begin accessing SaaS applications, private applications, APIs and enterprise data, ask how the vendor authenticates them, limits what they can access and continuously enforces those policies.


5. What does your product replace, integrate with or conflict with?

This one is worth asking before any PoC.

Find out exactly how the product coexists with your existing SWG, DLP, EDR, browser security and ZTNA.

Ask who performs TLS inspection, how traffic is routed and what happens when multiple endpoint agents attempt to control the same session.


Take the follow-up questions with you

The guide includes the follow-up question for each of the five questions, what the answer can expose, and what you should expect to hear from a strong solution.

It takes a couple of minutes to read.

It could save considerably more time evaluating the wrong architecture.